iPhone 앱에서 SSL 사용-수출 규정 준수
REST 웹 서비스와 통신 할 iPhone 앱을 만드는 중입니다. 사용자에게 민감한 일부 데이터 (이름, 주소, 나이 등)가 전송되기 때문에 SSL로 연결을 보호하려고합니다.
그러나 이전에 App Store 제출로 들어갔을 때 가장 먼저받은 질문은 "애플리케이션이 암호화를 사용합니까?"라는 것을 알았습니다. 이 질문 및 기타 후속 질문에 대한 답변에 따라 미국 수출 규정 준수가 필요할 수 있습니다.
우리 회사는 미국에 소재하지 않으며 미국 사무소도 없습니다.
이런 목적으로 SSL을 사용하여 앱을 제출 한 사람이 있습니까? 그렇다면 Apple 또는 미국 정부로부터 사용 허가를 받기 위해 어떤 조치를 취해야합니까?
2016 년 9 월 20 일 업데이트
ERN은 더 이상 필요하지 않으므로 많은 앱이 더 이상 미국 정부에 등록 할 필요가없는 것 같습니다. (여전히 2 년에 한 번씩 Part 742 보고서에 Supp. No. 8을 제출해야 할 수도 있습니다.) http://www.bis.doc.gov/InformationSecurity2016-updates
(이 점을 지적 해 주신 @EugenioDeHoyos 및 @ user3562927에게 감사드립니다!)
프랑스에서 판매하려면 여전히 프랑스 정부 등록이 필요합니다.
아이튠즈 커넥트 자주 묻는 질문은 이 변경 사항을 포함하도록 업데이트하고 내가 찾은 가장 읽을 참조입니다되고있다.
이전 답변
2010 년 여름부터 프로세스가 변경되었으며 John이 답변을 작성할 당시에 필요했던 CCATS가 아니라 지금 ERN이 필요합니다.
App에 대한 Apple iTunes 내보내기 제한을 참조하십시오 . iTunes 연결 FAQ에는 수출 규정 준수에 대한 유용한 정보도 많이 포함되어 있습니다.
이제 프랑스 앱 스토어에서 암호화를 사용하여 앱을 배포하는 데 적용되는 제한 사항도 있습니다 . devforums 의 itunes connect FAQ 및 French Export Compliance 스레드를 참조하세요 .
실제로 Apple로 돌아가서 SSL을 사용하는 모든 응용 프로그램 에는 승인 이 필요합니다 (불행히도). 애플리케이션이 단일 결제 거래에만 SSL을 사용하는 경우와 같은 몇 가지 예외가 있습니다.
대량 시장 암호화 CCATS Commodity Classification for iPhone Applications in 8 Easy Steps 및 iPhone Encryption Export Compliance for Apps Making HTTPS (TLS) Connections에 더 많은 정보가 있습니다 .
이 모든 답변은 2016 년 9 월 20 일 현재 사용되지 않습니다. 저는 방금 SNAP-R 직원 (정부)과 전화를 받았고 9 월 20 일에 새로운 법안이 내려 졌다고 말했습니다. 새로운 규정은 단순히 암호화를 사용하기 때문에 앱을 등록 할 필요가 없습니다.
나는 그들에게 내 앱 (게임)을 설명했고, 그들은 그것이 "EAR-99"라고 말했고, 이것은 내가 등록 할 필요가 없다는 것을 의미한다. Apple이 웹 사이트를 곧 업데이트 할 가능성이 높습니다. 하지만 그동안 SSL / HTTPS를 사용하기 때문에이 프로세스를 진행하려는 경우 지금 중지하십시오. 양식이 크게 변경 되었기 때문에 양식 작성에 성공하지 못할 것입니다.
이제 2017 년 11 월 ...
이것은 정말로 합법적 인 것이므로, 이것은 내가 유용하다고 생각한 것과 내가 어떻게 해석했는지에 대한 포인터입니다. 조언으로 받아들이지 마십시오 (아닙니다).
여기에 다른 답변에 언급 된 Apple FAQ는 훌륭한 출발점입니다 : https://itunespartner.apple.com/en/apps/faq/Managing%20Your%20Apps_Export%20Compliance
그러면 다음이 수행됩니다. iTunes Connect에서 앱으로 이동합니다. 상단의 '기능'탭을 선택하고 측면에서 '암호화'를 선택하십시오. 메인 페이지에서 'iOS 용 수출 규정 준수 문서 추가'를 클릭합니다. 첫 번째 질문 : '수출 규정 준수 : 앱이 암호화를 사용하도록 설계 되었습니까 ...' '예'를 선택하십시오. 다음 질문은 다음과 같습니다 (그리고 복사하여 붙여 넣기).
앱이 다음
중 하나를 충족합니까 : (a) 카테고리 5 파트 2에 따라 제공되는 하나 이상의 면제를받을 자격이 있습니다.
(b) 암호화 사용은 운영 체제 (iOS 또는 macOS) 내의 암호화로 제한됩니다.
(c) 전화 걸기 만 ( s) HTTPS를 통해
(d) 앱은 미국 및 / 또는 캐나다에서만 사용할 수 있습니다.
(c)는 (귀하의 질문에 따라) SSL 스타일 참조이므로이 질문에 예를 선택하십시오. [이 화면의 안내 하단에는 위의 FAQ 링크에 대한 링크가 있습니다.]
'예'를 선택하면 팝업 안내 상자 중 하나가 다음과 같이 표시됩니다.
ATS를 사용하거나 HTTPS로 전화를 거는 경우 연말 자체 분류 보고서를 미국 정부에 제출해야합니다. 더 알아보기
FAQ에서 주요 인용문은 다음과 같습니다.
미국에 거주하지 않는데 왜 내 앱에 암호화 검토가 필요합니까? 고국에서만 앱을 출시하는 경우 암호화 검토를 건너 뛸 수 있습니까?
귀하의 앱은 미국의 Apple 서버에 업로드됩니다. 즉, 귀하의 앱은 미국에서 수출되며 미국 수출 법의 적용을받습니다. 이 요구 사항은 자국 내에서만 배포 할 계획 인 경우에도 적용됩니다.
마지막 부분은 질문의 두 번째 부분에 대한 답이라고 생각합니다. 미국에 있지 않고 자국 외부에 배포 할 계획이 없더라도 여전히 준수해야합니다.
그래서 오늘 읽은 내용 (2017 년 11 월) 기준으로 iOS 앱에서 SSL (HTTPS)을 사용하는 경우 미국 이외 지역에서도 iTunes Connect 내에서 확인란을 선택해야합니다 ... (프로세스는 '기능 탭 '). 그 외에도 연간 자체 분류 보고서를 작성해야합니다.
이와 관련된 Apple FAQ의 링크는 현재 끊어졌지만 (이 글을 작성하면서)이 링크는 유용합니다 : https://www.bis.doc.gov/index.php/policy-guidance/product-guidance/high -성능 컴퓨터 / 223- 새-암호화 / 1238- 연간 자체 분류 보고서 제출 방법
이 페이지에는 보고서를 보낼 이메일 주소 (2 곳으로 보내야 함), 언제 보내야하는지, 어떤 형식과 정보를 보내야하는지 (조심스럽게 만들어진 매우 규정 된 .csv 파일) 찾을 수 없습니다. bis.doc.gov 검색 엔진을 사용했지만 '연말 자체 분류 보고서'를 검색하는 일반 검색 엔진을 사용하여 발견했습니다. 따라서이 특정 링크가 나중에 죽으면이 검색이 대체 항목을 찾는 데 도움이 될 수 있습니다. :)
SSL을 사용하여 iOS 앱용으로이 .csv 파일을 만드는 방법에 대한 자세한 내용은 아직 잘 모르겠습니다. 성공을 바라며 적절하다고 생각되면이 게시물을 세부 정보로 편집 할 것입니다.
이에 대해서는 링크 된 문서에서 https://www.bis.doc.gov/index.php/documents/new-encryption/1651-740-17-enc-table/file (확대해야 할 수도 있습니다. 읽기) 제출 요건이 일치하므로 관련 줄이 세 번째 줄 (b) (1)이라고 생각합니다. 그것은
Supp를 제출하십시오. 8, part 742, 이메일
이 문서에는 또한 ECCN 열이 있으며 관련 ECCN 번호가 5A002 점이라고 생각합니다.
이 다음 문서에는 올바른 ECCN 코드 선택에 대한 자세한 내용이 있습니다.
이 글을 읽으면 SSL이 앱의 작은 부분으로 사용되는 경우 코드 5A002.a.4와 관련이 있습니다.
최신 정보:
따라서 bis.doc.gov 지침의 맨 아래에 .csv 파일 생성에 대한 설명은 다음과 같습니다.
- First line of the annual self-classification report must consist of the following 12 entries: PRODUCT NAME, MODEL NUMBER, MANUFACTURER, ECCN, AUTHORIZATION TYPE, ITEM TYPE, SUBMITTER NAME, TELEPHONE NUMBER, E-MAIL ADDRESS, MAILING ADDRESS, NON-U.S. COMPONENTS, NON-U.S. MANUFACTURING LOCATIONS.
- No entry may be left blank.
- PRODUCT NAME and ECCN must be completed.
- For MODEL NUMBER and MANUFACTURER, if necessary, enter "NONE" or "N/A".
- For AUTHORIZATION TYPE, enter ENC or MMKT.
- For ITEM TYPE, pick from the list of item types provided in the Supp. 8 to Part 742 (a)(6).
- Column headers SUBMITTER NAME through NON-U.S. MANUFACTURING LOCATIONS relate to the company as a whole, and thus should be entered the same for each product (i.e., only one point of contact, one ‘YES’ or ‘NO’ answer to whether any of the reported products incorporate non-U.S. sourced encryption components, and one list of non-U.S. manufacturing locations, is required for the report). Duplicate this information into each row of the spreadsheet
- The only permitted use of a comma is the necessary separator between the 12 entries for each line item. The only commas allowed are the ones inserted automatically during spreadsheet conversion.
Using Supplement No. 8 to Part 742—Self-Classification Report for Encryption Items for further guidance, I got to a .csv file like this:
PRODUCT NAME, MODEL NUMBER, MANUFACTURER, ECCN, AUTHORIZATION TYPE, ITEM TYPE, SUBMITTER NAME, TELEPHONE NUMBER, E-MAIL ADDRESS, MAILING ADDRESS, NON-U.S. COMPONENTS, NON-U.S. MANUFACTURING LOCATIONS
[my-app-name] iOS App,[my-App-version-number],SELF,5A002,ENC,Link encryption,[My-name],[my-phone-number],[my-email],[my address with no commas],YES,[my-location]
Note that this should be well a well formed .csv file which this isn't quite. I suggest creating something in a spreadsheet and saving as a .csv
Also note that this is not an advised result - it's my best interpretation as an unqualified individual having had no advice. The example .csv at the bottom of the bis.doc.gov guidance helped me further and seemed to suggest that the ECCN could just be 5A002 without further detail. The ITEM TYPE has to be picked from the list in Supplement number 8 - something else might fit the nature of your App better. I wasn't so sure on MODEL NUMBER, but the example looked like it was using version number type descriptions. Maybe App Apple ID would be better here. Given it's optional, it might not matter...
UPDATE (Jan 2019): Finally made my submission for 2018 and went for:
PRODUCT NAME, MODEL NUMBER, MANUFACTURER, ECCN, AUTHORIZATION TYPE, ITEM TYPE, SUBMITTER NAME, TELEPHONE NUMBER, E-MAIL ADDRESS, MAILING ADDRESS, NON-U.S. COMPONENTS, NON-U.S. MANUFACTURING LOCATIONS
[my-app-name] iOS App,N/A,SELF,5A002,ENC,Link encryption,[My-name],[my-phone-number],[my-email],[my address with no commas],NO,[my-location]
The changes were to put 'N/A' as the Model Number and 'NO' for NON-U.S. COMPONENTS. 'NO' because there are no bought-in components to my App (US or NON-US) - the encryption code is just the iOS encryption library.
I found this article from someone who went through the process recently (Dec 2015) extremely helpful. The overall consensus seems to be that you really do need to go through this process even if you are just using a REST call that utilizes SSL. This article will help you run through the process quickly.
https://carouselapps.com/2015/12/15/legally-submit-app-apples-app-store-uses-encryption-obtain-ern/
I ran across this question earlier today and thought I'd come back to report my experience.
Check out: http://tigelane.blogspot.com/2011/01/apple-itunes-export-restrictions-on.html for a procedure that worked well for me (be sure to read the whole thing including the comments -- there have been some changes since the original post, mostly for the better, and the updated info is in the comments).
The process is pretty streamlined now (except for Safari and Chrome not recognizing their own site's SSL certificate. A little ironic there. :-); I got approval about 10-15 minutes after submitting the info.
I'd guess that this has become a routine thing for them (at least if you're only using SSL rather than some kind of exotic crypto).
Because the app is setting up and using secure SSL connections it is considered an encryption product. The US export controls depend on whether you use encryption, not where you find it. It doesn't matter that you are using a built-in function instead of writing your own, using a commercial library, or using a specialized processor--it is still an encryption item.
Check out the BIS web site at www.bis.doc.gov/encryption or call the help desk at 202-482-0707 if you want to discuss the particulars of your app. If you find out you need an encryption classification then the link for the SNAPR is there too.
참고URL : https://stackoverflow.com/questions/2128927/using-ssl-in-an-iphone-app-export-compliance
'Program Club' 카테고리의 다른 글
| 루비 : 콜론 전후 (0) | 2020.10.24 |
|---|---|
| Java에서 URL 연결은 언제 종료됩니까? (0) | 2020.10.24 |
| Vim-선택한 범위의 행 수 (0) | 2020.10.23 |
| C에서 nanosleep ()을 사용하는 방법? (0) | 2020.10.23 |
| gcc에서 인수가없는 것으로 정의 된 함수에 인수를 전달할 수있는 이유는 무엇입니까? (0) | 2020.10.23 |